Blog
Compliance
Cyber Essentials
August 5, 2026
Approx min read

Cyber Essentials renewal 2026: what a lapse costs you

Cyber Essentials certificates run for twelve months. The renewal most UK suppliers are booking this autumn is the first they will sit under the Danzell question set, and it is marked more strictly than the assessment that produced the certificate they currently hold.

That combination catches organisations out. Most of the underlying requirements are familiar from previous years. The change sits in how three of them are now marked.

Three answers that now fail a Cyber Essentials assessment outright

Since late April 2026, new assessment accounts run on the Danzell question set, aligned to Requirements for IT Infrastructure v3.3. Three requirements cause automatic failure regardless of how well the rest of the assessment scores.

Multi-factor authentication is mandatory on all cloud services that offer it, whatever the cost of enabling it. Question A6.4 requires high-risk and critical security updates and vulnerability fixes for operating systems and for router and firewall firmware to be installed within 14 days of release. Question A6.5 applies the same 14-day rule to applications, including their associated files and extensions.

Version 3.3 also clarifies how cloud services are defined, simplifies the scoping language, replaces the previous focus on web applications with a section covering application development, revises the backup guidance and puts more weight on passwordless authentication. Scope decisions that were defensible last year are worth rechecking against the new wording before you answer anything.

Cyber Essentials Plus tightened too. Where an initial sample fails, remediation now has to be applied across the full scope and the retest runs on a new sample of devices. Once Cyber Essentials Plus testing has started, you can no longer amend the verified self-assessment responses underneath it.

The Cyber Essentials transition window closes this autumn

Assessment accounts created before 27 April 2026 continue on the previous question set. Once an account is created, you have six months to complete the assessment.

The last of those six-month windows close during October 2026. If you opened an account in the weeks before the change and have not finished, that window is the only remaining route to certification under the old marking, and it is closing. Everything after it runs on Danzell.

Where a lapsed certificate turns into a commercial problem

A certificate is a date on a contract. Public sector buyers, defence supply chains, insurers and enterprise procurement teams ask for current certification, and current means valid on the day they check.

The damage happens in the gap. If your certificate expires on its anniversary and the re-assessment takes an extra three weeks because multi-factor authentication was missing on one cloud service in scope, you have three weeks during which anyone checking sees an organisation without a certificate. Procurement teams check against the date they need it. A gap that falls across a bid window has to be explained at exactly the moment you want to be talking about something else.

There is a second-order effect on Cyber Essentials Plus. The Plus audit has to be completed within three months of your Cyber Essentials certification, so a delayed basic renewal pushes the Plus date with it. Plus is the level many enterprise and public sector buyers specify, and it is the one with the longer booking lead time.

Renewals also tend to be under-planned because the first certification felt straightforward. The scope has usually moved since then. New cloud services, new starters, a change of device management, a router replacement. Under the previous marking those drifts produced observations. Under Danzell, two of them produce a fail.

Protecting your Cyber Essentials renewal date

Start from the expiry date and work back far enough to absorb one round of remediation and a retest. The organisations that renew smoothly are the ones that treat the assessment as the last step rather than the first.

Before you open the assessment account, do four things.

Audit multi-factor authentication across every cloud service in scope, including the ones a single team adopted without telling anyone. The question asks about services that offer it, so the cost of the licence tier is not an accepted reason for its absence.

Check patching against a 14-day clock, separately for operating systems, for router and firewall firmware, and for applications and their extensions. Then check you can evidence it, because an assertion without a record behind it is a weak answer.

Re-read your scope against the version 3.3 wording on cloud services and application development. If your scope statement was written before this year, it was written against different definitions.

Confirm which question set your account sits on. If you hold an account opened before 27 April 2026, finish it inside its six months.

For the full requirement detail, see the Cyber Essentials framework page. For how the renewal sits alongside other deadlines you are working to, see the piece on how long each standard takes.

How Naq keeps your Cyber Essentials certificate current

Naq is a Cyber Essentials Certifying Body via IASME, so both Cyber Essentials and Cyber Essentials Plus run through the platform with the assessment and its supporting evidence in the same place.

Controls sit against the requirements they satisfy, with the evidence attached, so the state of multi-factor authentication coverage and patching is something you can look at before an assessor does. Every change is recorded on the activity stream, with previous and new values, which is what turns an answer into something you can stand behind. The same controls and evidence count towards ISO 27001, the NHS DSPT and your GDPR obligations, so the work behind a renewal is not spent once.

If your certificate expires in the next few months, book a fifteen-minute demo and we will walk your current scope against the Danzell requirements.